CH20 - Course Quiz Flashcards

1
Q

A packet sniffer is a program that queries a network interface and collects packets in a file called a ______________ file?

capture
log
flow cache
syslog

A

capture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In NetFlow, flows are stored in a _____________?

log
flow cache
packet
frame

A

flow cache

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An agent can solicit information from an NMS with the ____________ protocol data unit (PDU)?

set
get
response
trap

A

trap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

It is a good idea to give root access to critical log files for performance reasons?

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The SNMP Manager requests and processes information from the ____________ devices?

opened
closed
managed
privileged

A

managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which underlying protocol enables network monitoring tools to work?

TCP
SNMP
UDP
SMTP

A

SNMP (Simple Network Management Protocol)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A single flow in NetFlow is a sequence of packets from one specific place to another?

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which program is an example of a powerful and open source protocol analyzer?

wireshark
syslog
cisco network assistant (CNA)
PerfMon

A

Wireshark

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

On which port does NMS receive/listen?

160
161
162
163

A

162 (Network Management System)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which tool was developed for packet flow monitoring and was subsequently included in Cisco Routers and Switches?

NetFlow
Wireshark
PerfMon
Syslog

A

NetFlow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Interface monitors track the quality and utilization of traffic through a physical _____________ or ports on a single device?

network interface card (NIC)
port
switch
frame

A

port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In the case of a Switch, it is typical for packet sniffers to connect to an interface using a _____________ port?

virtual
mirrored
promiscuous
closed

A

mirrored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which one function is sent when an SNMP Manager wants to query an agent?

Set
Get
Response
Trap

A

Get

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which term does Performance Monitor use when referring to the monitored aspect of the System?

facilities
counters
modes
characteristics

A

counters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The current version of SNMP is SNMPv3?

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which tool is used to create a baseline on Windows Systems?

Performance Monitor
Cacti
Syslog
NetFlow

A

Performance Monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What User Datagram Protocol (UDP) ports does SNMP use for unsecure communication?

61 and 62
610 and 612
161 and 162
10162 and 10161

A

161 and 162

Explanation:
Secure TLS SNMP = 10161 and 10162

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which program is an example of graphing tool that could be used to show everything about specific switches?

NetFlow
Cacti
Syslog
Cisco Network Assistant (CNA)

A

Cacti

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

An SNMP System has up to ______________ core functions (depending on the version of SNMP)?

two
four
six
eight

A

eight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Performance Monitors use system ____________ files to track performance over time?

Access Control List (ACL)
flow cache
routing table
log

A

log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which core function is sent by the agent after the SNMP manager queries an agent with a GetRequest or GetNextRequest?

Set
Get
Response
Trap

A

Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which sensors monitor environmental factors, such as external temperatures, humidity levels in the server room, issues with electrical load, and more?

interface
environmental
response
trap

A

environmental

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

All operating systems come with some form of baseline tools?

True
False

A

True

24
Q

NetFlow is another name for SNMP?

True
False

A

False

25
Q

Which interface statistic value increases when packets are received that are shorter than Ethernet’s minimum size of 64 bytes?

encapsulation
link
runts
giants

A

runts

26
Q

An NMS can tell an agent to make changes to the information it queries and sends, called variables, through a ________________ protocol data unit (PDU)?

Set
Get
Response
Trap

A

Set

27
Q

Managed devices run software called ________________?

robots
switches
drones
agents

A

agents

28
Q

In NetFlow, a single flow is a sequence of _________________ from one specific place to another?

frames
packets
segments
cylinders

A

packets

29
Q

If you want to know how hard your network is working, us a ________________?

management information base
flow cache
performance manager
interface monitor

A

interface monitor

30
Q

A ___________ is a centralized location for technicians and administrators, used to manage all aspects of the Network?

A

Network Operations Center (NOC)

31
Q

On an SNMP managed network, a _________________ program could create graphs and diagrams that display any set of the data received?

A

graphing

32
Q

SNMP adds security using _______________?

A

Transport Layer Security (TLS)

33
Q

In packet flow monitrong, a single __________________ is a sequence of packets from one specific place to another?

A

flow

34
Q

With interface monitoring, ___________________ references how much of the port’s total bandwidth is being used?

A

utilization

35
Q

______________________ track the bandwidth and utilization of one or more interfaces on one or more devices?

A

Interface Monitor

36
Q

The most common macOS and Linux Performance Monitor tool is called ___________________?

A

Syslog

37
Q

A ____________________ tracks the performance of some aspect of a system over time and lets you know when things aren’t normal?

A

Performance Monitor

38
Q

__________________________ are the computers within a Network that are receiving the most data?

A

Top Listeners

39
Q

SNMP uses _______________________ to categorize the data that can be queried (and subsequently analyzed)?

A

Management Information Bases (MIB)

40
Q

The ____________________ is the defacto network management protocol for TCP/IP Networks?

A

Simple Network Management Protocol (SNMP)

41
Q

The _________________ utility can quickly query any SNMP device directly from a computer’s terminal?

A

snmpwalk

42
Q

The common term for each of the SNMP System core functions is ________________?

A

Protocol Data Unit (PDU)

43
Q

Describe the ports SNMP uses for unsecure and secure communications?

A

SNMP Managers use UDP Ports 162 or 10162 with Transport Layer Security (TLS).

SNMP Agents use Ports 161 or 10161 with Transport Layer Security (TLS).

44
Q

List the four major types of monitoring tools?

A

Packet (Sniffers)
Protocol (Analyzers)
(Interface) Monitors
(Performance) Monitors

45
Q

Describe a baseline and explain how a baseline can point to problems on a Server or the Network?

A

A Baseline is a log of normal operational performance to give you a picture of your network and servers when they are working correctly.
A major change in these values can point to problems on a server or network as a whole.

46
Q

How should an administrator enable NetFlow in order to use it?

A

NetFlow is Enabled on the Device, if the device doesn’t support NetFlow, you can use stand-alone probes that can monitor maintenance ports on the unsupported device and send the information to the NetFlow collector.

47
Q

Identify three components in a Managed Network?

A

Managed (Devices)
SNMP (Manager)
SNMP (Agent)

48
Q

Describe the two most common performance monitor tools?

A

Windows Performance Monitor (perfmon.exe)

Syslog (found in macOS and Linux)

49
Q

What are SNMP Alerts and how are they disseminated?

A

Alerts, Notifications - they are sent directly to techs - via SMS text messaging and email alerts - when their intervention is required.

50
Q

Describe the key component that enables performance monitors to track performance over time?

A

Logs - They store information about the performance of some particular aspect of a system.

51
Q

Briefly list the versions of SNMP?

A

SNMPv1
SNMPv2
SNMPv3

52
Q

Explain the purpose of applications like Cacti?

A

They enable you to see very quickly essential facts about your Network Hardware.

53
Q

Briefly describe a packet sniffer?

A

It’s a program that queries a Network interface and collects packets in a file called a capture file. Might sit on a single computer or perhaps on a Router or a dedicated piece of hardware.

54
Q

Explain why access to active logs must be carefully controlled and explain how this can be accomplished?

A

Because logs often contain private or sensitive data.

55
Q

Identify additional terms for utilities that analyze packets?

A

Packet (Sniffer)
(Packet) Aalyzer
(Protocol) Analyzer
(Network) Analyzer